Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. tactic: TA0005 ✕ technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Defense Evasion |
| Analytics BIOC | A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Persistence |
| Analytics | Short-lived Azure AD user account An Azure AD user was created and deleted within a short period of time. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics | Short-lived user account A user was created and deleted within a short period of time. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. | Medium | Identity Analytics | AzureAD | Initial Access, Defense Evasion |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |
| BIOC | User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |